CVE-2026-32922 | OpenClaw up to 2026.3.10 device.token.rotate privileges assignment (GHSA-4jpw-hj22-2xmc / EUVD-2026-17003)
A vulnerability has been found in OpenClaw up to 2026.3.10 and classified as critical. This issue affects the function device.token.rotate. Performing a manipulation results in incorrect privilege assignment.
This vulnerability is known as CVE-2026-32922. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.